CVE-2022-40134
published 2023-01-30CVE-2022-40134: An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated…
PriorityP417medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.20%
9.5th percentile
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Affected
337 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | bios | — | — |
| lenovo | ideacentre_3-07ada05_firmware | — | — |
| lenovo | ideacentre_3-07imb05_firmware | — | — |
| lenovo | ideacentre_3_07iab7_firmware | — | — |
| lenovo | ideacentre_5-14acn6_firmware | — | — |
| lenovo | ideacentre_5-14are05_firmware | — | — |
| lenovo | ideacentre_5-14imb05_firmware | — | — |
| lenovo | ideacentre_5-14iob6_firmware | — | — |
| lenovo | ideacentre_510s-07icb_firmware | — | — |
| lenovo | ideacentre_510s-07icb_firmware | — | — |
| lenovo | ideacentre_510s-07ick_firmware | — | — |
| lenovo | ideacentre_5_14iab7_firmware | — | — |
| lenovo | ideacentre_a340-22igm_firmware | — | — |
| lenovo | ideacentre_a340-24igm_firmware | — | — |
| lenovo | ideacentre_c5-14imb05_firmware | — | — |
| lenovo | ideacentre_creator_5-14iob6_firmware | — | — |
| lenovo | ideacentre_g5-14amr05_firmware | — | — |
| lenovo | ideacentre_g5-14imb05_firmware | — | — |
| lenovo | ideacentre_gaming_5-14acn6_firmware | — | — |
| lenovo | ideacentre_gaming_5-14iob6_firmware | — | — |
| lenovo | ideacentre_gaming_5_17acn7_firmware | — | — |
| lenovo | ideacentre_gaming_5_17iab7_firmware | — | — |
| lenovo | legion_c530-19icb_firmware | — | — |
| lenovo | legion_t5-26iob6_firmware | — | — |
| lenovo | legion_t5-28icb05_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Qualys
Remediate Your Vulnerable Lenovo Systems with Qualys Custom Assessment and Remediation
blogs_qualys·2022-09-28·CVSS 7.8
CVE-2021-28216 [HIGH] Remediate Your Vulnerable Lenovo Systems with Qualys Custom Assessment and Remediation
## Table of Contents
How Qualys Can Help
Conclusion
Try It for Free
Read More:
Contributors
Lenovo disclosed Multi-Vendor BIOS Security Vulnerabilities in September 2022 that affect multiple Lenovo devices. These are high severity vulnerabilities that have the potential of resulting in information disclosure, privilege escalation, and denial of service. Here are the related CVEs:
CVE-2021-28216 – Tianocore reported a fixed pointer vulnerability in TianoCore EDK II BIOS that may allow an attacker with local access and elevated privileges to execute arbitrary code
CVE-2022-40137 – A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code
CVE-2022-40134 – An information leak vulnerability i
Qualys
Remediate Your Vulnerable Lenovo Systems with Qualys Custom Assessment and Remediation | Qualys
blogs_qualys·2022-09-28·CVSS 7.8
CVE-2021-28216 [HIGH] Remediate Your Vulnerable Lenovo Systems with Qualys Custom Assessment and Remediation | Qualys
#### Table of Contents
- How Qualys Can Help
- Conclusion
- Try It for Free
- Read More:
- Contributors
Lenovo disclosed Multi-Vendor BIOS Security Vulnerabilities in September 2022 that affect multiple Lenovo devices. These are high severity vulnerabilities that have the potential of resulting in information disclosure, privilege escalation, and denial of service. Here are the related CVEs:
- CVE-2021-28216 – Tianocore reported a fixed pointer vulnerability in TianoCore EDK II BIOS that may allow an attacker with local access and elevated privileges to execute arbitrary code
- CVE-2022-40137 – A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code
- CVE-2022-40134 – An information leak vu
2023-01-30
Published